Graphic of people using devices connected to secure server data and files protected by a shield icon.

IRAP PROTECTED-level collaboration platforms: A guide for government leaders

IRAP certification proves a platform meets ASD security rules for PROTECTED data. See how top collaboration platforms compare.

Cover of the Salesforce State of Marketing report
Uncover the latest insights on the state of public services and the future of agentic AI.

Key differences between OFFICIAL: Sensitive and PROTECTED classifications

Criteria OFFICIAL: Sensitive PROTECTED
Data type and impact Routine business operations, internal communications, limited distribution of unclassified data Highly sensitive data, where a compromise would cause serious damage to national security
Compliance expectation Standard, robust commercial security practices Strict adherence to expanded ISM controls
Data at rest (storage) Can be stored in standard public, multi-tenant cloud environments with industry-standard encryption Requires highly isolated storage environments with end-to-end encryption generated and held exclusively by the agency
Data in transit (transmission) Standard commercial encryption, such as standard TLS Must occur over highly secure networks
Sovereignty Data and metadata can reside in offshore data centres Data and metadata must remain wholly within Australia

Build public trust and connection with Agentforce for Public Sector.

Modernise government service and increase operational efficiency with proactive agents and automation. Use Salesforce software for government to unify and harmonise data on a compliance-enabled cloud. Innovate faster with a low code application platform for government.

Comparison of top collaboration platforms

Platform Local IRAP status Primary data residency Identity and access strengths Integration depth and footprint
Salesforce + Slack PROTECTED, assessed on local Hyperforce architecture 100% onshore via Australian Hyperforce zones Robust conditional access, granular session controls, full Salesforce Shield key governance Deep structural integration, combining conversational chat natively with enterprise core records and AI agents
Microsoft 365 + Teams PROTECTED, assessed across core enterprise suites Onshore across dedicated Australian data centres Industry-standard via Azure AD/Entra ID Exceptional native document co-authoring and telephony integration
Google Workspace OFFICIAL: sensitive; individual agencies pursue custom PROTECTED plans Selected storage locales can be pinned onshore Strong cloud-native identity baselines, hardware security key support Lightweight, browser-first collaboration, though deep legacy enterprise systems require extensive middleware
Atlassian Cloud IRAP-assessed; specific tiers support PROTECTED status Local data residency controls are available for primary data objects Centralised via Atlassian Access, supporting standard SAML single sign-on Potential leader for technical project tracking, agile development pipelines, and DevOps workflows
Cisco Webex PROTECTED, assessed via specialised architectures Onshore media and data processing elements are pinned locally Enterprise-grade identity management with strict end-to-end cryptographic boundaries Built intentionally for hardware-heavy conference spaces and high-fidelity video streams
The Total Economic Impact of Salesforce Case Management Solutions for Government
See how government agencies can realise cost savings with Salesforce.

FAQs

An IRAP-assessed collaboration platform is a digital communication and workplace solution that has been evaluated by a certified, independent third-party auditor using the Information Security Registered Assessors Program (IRAP) framework. This process determines whether the platform satisfies the compliance requirements of the Australian Signals Directorate’s (ASD) Information Security Manual (ISM) controls.

No. An IRAP assessment is simply an independent point-in-time audit report outlining a platform’s security capabilities. It doesn’t translate into an automatic, permanent pass or fail or a stamp of approval from the government.

No, it isn’t. While storing core database files is mandatory, the ISM also dictates that all forms of metadata, data processing, and operational personnel are native as well. Any form of offshore functionality within a data lifecycle could be enough to jeopardise PROTECTED-level compliance.

No. An IRAP assessment only covers the specific software modules and deployment models explicitly defined in the assessment’s scope document. If your cloud security team installs third-party apps or marketplace plugins, they’re excluded from the core vendor’s assessment and could make your entire operation non-compliant.